๐Ÿ” CVE Alert

CVE-2026-91829

UNKNOWN 0.0

Subscribe to Comments < 2.3.3 - Reflected XSS via 'ref' Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Subscribe to Comments WordPress plugin before 2.3.3 does not properly validate a parameter before reflecting it into a link target, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting via a crafted URL against anyone who clicks it, including administrators.

Vendor unknown
Product subscribe to comments
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown subscribe to comments

Be the first to know when new unknown vulnerabilities affecting unknown subscribe to comments are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Subscribe to Comments
0 < 2.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/1ed0314d-9871-4914-bb9c-ff894ea4c400/

Credits

Het Kalariya WPScan